Information about the Controller who processes and stores your data:
Administrator Information:
Picture name: Knowbox Ltd.
UIC/BULSTAT: 203696383
Registered office and management address: gr. Sofia, Sredets district, 47, floor. 1
Address for correspondence: gr. Sofia, Sredets district, 47, floor. 1
Email: militza.kraynova@knowbox.bg
Website: shop.knowbox.bg
Information on the competent data protection supervisory authority:
Name: Data Protection Commission
Registered office and management address: gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2
Address for correspondence: gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2
Phone: 02 915 3 518
Website: www.cpdp.bg
Terms used
- "Personal data" - any information relating to an identified or identifiable living individual. Individual data which, when aggregated, may lead to the identification of a specific individual also constitute personal data. Examples of such are: first and last name, home address, email address identity card number, location data, Internet Protocol (IP) address.
- "Online shop" - a distinct location on the World Wide Web, accessible via its Uniform Resource Locator (URL) using HTTP, HTTPS or other standardized protocol, and containing files, programs, text, sound, picture, image or other materials and resources, and the ability to enter into a remote purchase contract
- "Processing" - any operation or set of operations which is performed upon personal data or a set of personal data, whether or not by automatic means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- "Administrator." - a natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its determination may be laid down in Union or Member State law.
Grounds for collection of your personal data by the Controller.
Art.1. After obtaining your consent and in connection with compliance with a legal obligation, the Controller collects and processes your personal data in connection with its use on the basis of Art. 1, Regulation (EU) 2016/679 (GDPR) and more specifically:
to the following:
- Explicit consent obtained from you as a customer
- Performance of the Administrator's duties
- Compliance with a legal obligation applicable to the Administrator
- For the purposes of the legitimate interest of the Controller
Purposes and principles of collecting, processing and storing your personal data.
Art. 2 (1) We collect and process the personal data you provide to us in connection with your use of the online store for the following purposes:
- Accounting purposes;
- Statistical Objectives;
- Information Security Protection;
- Execution of a contract of sale;
- Performing a forwarding service for the purpose of delivery;
(2) We comply with the following principles when processing your personal data:
- Principle of legality, good faith and transparency - the collection, processing and storage of personal data is carried out in accordance with the regulatory framework. Prior to the collection of personal data from the subject, information shall be provided to the subject on the purposes for which the personal data are collected/processed/storage.
- Limitation of the purposes of processing - the collection and processing of personal data shall consist in the collection of data to the minimum extent necessary to fulfil the purposes for which it is collected.
- Accuracy and timeliness of data - data is processed and stored with due regard for its accuracy and to ensure that it is kept up to date and, where necessary, inaccurate personal data is deleted and/or corrected in a timely manner;
- Integrity and confidentiality of processing and ensuring an appropriate level of security of personal data - the use of only such technical means of protection or the application of other appropriate measures which ensure that only personal data necessary for each specific purpose are processed and the data are kept for the minimum period strictly necessary to achieve the purpose. Also, the processing of personal data shall be carried out in a manner which ensures an adequate level of security of personal data, including protection against unauthorised or unlawful processing.
(3) The controller shall not collect or process personal data relating to the following:
- Racial or ethnic origin;
- Political, religious or philosophical beliefs, or membership of trade unions, political or non-governmental organisations;
- Genetic and biometric data, health data or data on sex life or sexual orientation.
(4) Personal data is collected by the Controller from the persons to whom it relates.
(5) The Company does not collect data about persons under the age of 16 except with the express consent of their parent or legal guardian.
(6) The controller processes the following categories of personal data and information in relation to the purposes and grounds set out below.
Personal data collected, processed and stored and the period of storage.
Art. 3 (1) We collect the following personal data: e-mail, name, address
Purpose for which the data is collected:
- Conclusion and execution of the distance purchase contract;
Legal basis - Art. 6, para. 1 (b) GDPR
(2) We collect the following personal data from you: e-mail:
Purpose for which the data is collected:
- Sending information with current news and/or promotional terms for services and/or products provided by the Administrator;
Legal basis - Art. 6, para. 1 (b) GDPR
(2) The content received from users who have provided their personal data on the basis of paragraph 1 may not be sent more frequently than once a week by the Controller.
(3) Customer data and documents on transactions and operations carried out, as well as documents relating to the establishment and maintenance of commercial or professional relationships shall be kept for a period of 5 years.
(4) Administrator keep your personal data that it has collected only for the period necessary to achieve the purposes set out in this Policy, and where it has a legal right or obligation to keep it for a longer period. Various factors determine the length of retention, such as: the duration of service provision, if necessary in order to establish, exercise or defend our legal claims, or whether we have a legal obligation to retain the data. The periods are as follows:
- up to 2 years for personal data shared by users on the website, subject to the user's explicit consent to share the relevant data
- 5 years upon expiry of the limitation periods for bringing claims set out in the Obligations and Contracts Act;
- 10 years under the Accounting Act for storage and processing of accounting data;
- 5 years obligations to provide information to the court, competent state authorities and other grounds provided for in the legislation in force;
- Data on clients and documents on transactions and operations carried out, as well as documents relating to the establishment and maintenance of commercial or professional relations shall be kept for a period of 5 years (Article 171, paragraph 1 of the Tax Code).
User Rights.
Art. 4 Right of access to personal information - Users have the right to receive a copy of the personal information we hold about them, and information about how we use it. Any user may exercise this right by freely submitting their request, via email to the Administrator.
Art. 5 (1) Right to correct personal information - Users have the right to ask us to correct the personal information we hold about them if it is inaccurate or incomplete.
(2) The user's right to rectify his/her personal information may be exercised by means of an email notification addressed to the Administrator, which must comply with the following:
- Associated Email;
- Data you wish to be corrected;
- The data you wish to apply for the required correction;
Art. 6 (1) The right to erasure of personal information - sometimes called the "right to be forgotten". This right enables Users to request that their personal information be deleted or removed from our systems and records. However, this right only applies in certain circumstances.
(2) The user's right to request deletion of personal information may be exercised by sending the following required content to the contact email address of the Administrator:
- The data you wish to be deleted;
Art. 7 (1) Right to restrict the processing of personal information - Users can ask us to stop using their personal information. However, this right only applies in certain circumstances.
(2) This right applies in the event that:
- Challenge the accuracy of the personal data, for a period that allows the Controller to verify the accuracy of the personal data;
- the processing is unlawful, but you do not wish the personal data to be erased, but only for its use to be restricted;
- The controller no longer needs the personal data for processing purposes, but you require it for the establishment, exercise or defence of legal claims;
- You have objected to processing pending verification that the legitimate grounds of the Controller override your interests.
Art. 8 (1) Right to data portability - allows you to receive your personal information in a format that allows you to transfer that personal information to another organisation.
(2) In order to exercise the right of portability, you should send a list of the data you wish to exercise to the email address provided for contacting the Controller.
Art. 9 Right to object to the processing of personal information - You may object at any time to the processing of personal data by the Data Controller which relates to you, including if it is processed for direct marketing purposes.
Art. 10 (1) Right to withdraw consent to the processing of personal information - applies only where we process personal information on the basis of your consent. If you do not want all or part of your personal data to continue to be processed by the Company for any or all of the processing purposes, you may withdraw your consent to processing at any time.
(2) The controller may ask you to verify your identity and identity with the data subject.
(3) By withdrawing your consent to the processing of personal data, you will again be able to view the information available on the website.
(4) You may withdraw your consent to the processing of your personal data for direct marketing purposes at any time.
(5) The withdrawal of consent shall not affect the lawfulness of the processing of personal data that the Controller has carried out up to that point.
(6) In order to exercise the right to withdraw consent to the processing of personal information, you should address your wish by sending a text explicitly declaring your wish to do so.
Persons to whom your personal data is provided
Art. 11 (1) In connection with the fulfilment of its legal obligations, the maintenance of the website and the professional performance of the services offered, the Administrator may, without requesting explicit additional consent from the user concerned, provide personal data to its employees, as well as to other legal entities that are related parties within the meaning of the Commercial Act, and to: the National Revenue Agency, State Agency for National Security, freight forwarders, accounting firms, law firms that assist in our operations and commercial companies that maintain the online store and IT systems information security.
(2) The controller shall provide personal data to other third parties if it is required to do so by applicable law, court order, subpoena or governmental act.
(3) The Controller may provide personal data if it deems such action to be necessary to protect legal rights, protect your safety or that of others, or as part of a criminal or other legal investigation or proceeding in the Republic of Bulgaria or abroad.
Art. 12 In case of transfer of personal data to third partiesThe Authority shall put in place appropriate technical and organisational measures to ensure consumer rights and the protection of personal data. The controller shall select only third parties that have taken the necessary safeguards to protect the personal data provided to them and, in view of the risks involved, to ensure an adequate level of security, including where appropriate:
- pseudonymisation and encryption of personal data;
- the ability to ensure the continued confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to promptly restore the availability of and access to personal data in the event of a physical or technical incident;
- a process of regularly testing, assessing and evaluating the effectiveness of technical and organisational measures to ensure the security of processing.
Art. 13 (1) The controller shall not transfer personal data provided to it by data subjects to third countries outside the European Union. If such a transfer is necessary, the Data Controller will inform the data subject in writing in advance of the transfer and of the reason for the transfer.
(2) It is possible to provide analytical data to third parties based on the use of cookies. If you would like to find out more about which cookies we use, visit our Cookie Policy.
(3) As a general rule, your personal data is stored and processed throughout the European Union and the European Economic Area (EEA). In the event that your personal data is transferred outside the European Union or the EEA, the transfer will be subject to any of the following safeguards:
- Binding corporate rules from the relevant supervisory authority;
- On the basis of standard contractual terms adopted by the European Commission;
- An approved code of conduct or certification mechanism in the presence of legally binding and enforceable obligations on the third party processor.
(4) If we determine that one of these measures is not sufficient to provide an adequate level of protection, we will, on a case-by-case basis, adopt additional technical and/or organisational security measures in accordance with the recommendations of the European Commission. You can contact us at any time using the contact details listed above to find out more about the countries to which we transfer your data and the safeguards we have in place in respect of these transfers.
Art. 14 (1) The Administrator reserves the right to modify and update the Privacy Policy, and users are informed of the changes through a notice on the website.
(2) The parties agree that any additions and amendments to this document will be effective against the User after their publication on the Administrator's website and if the User does not declare within 14 days of their publication that they reject them,
Art. 15 In the event of a breach of your rights under the above or applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Commission as follows:
|
Name |
Data Protection Commission |
|
Registered office and registered office |
gr. 1592 Sofia Blvd. "Proff. Tsvetan Lazarov" № 2 |
|
Phone |
02 915 3 518 |
|
|
kzld@cpdp.bg |
|
Website |
www.cpdp.bg |
This Privacy Policy was adopted on 02.01.2024.
